Impact
An authenticated user can exploit a privilege escalation flaw that allows them to reference another user’s AI Assistant conversation identifier. When a hard‑to‑guess identifier is supplied, the system permits reading or changing a conversation that is not owned by the requester. This flaw results in unauthorized data modification and therefore a breach of data integrity rather than direct disclosure, classified as CWE‑639.
Affected Systems
Kibana from Elastic is affected; the advisory does not enumerate specific version numbers, so any current instance that has the vulnerable code path is potentially impacted.
Risk and Exploitability
The CVSS score of 4.2 indicates a moderate severity assessment, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Because exploitation requires an authenticated user and knowledge of a specific conversation identifier that is difficult to guess, the likelihood of real‑world exploitation is low. Nonetheless, privileged users could intentionally or inadvertently modify another user’s data if the identifier is exposed through other application functions.
OpenCVE Enrichment